check / check (push) Successful in 3m1s
A utun tunnel counted as the VPN whenever it was up with a routable IPv4 address, so idle Tailscale or a tunnel left behind by a disconnected client became the VPN pane and its probes failed. A tunnel is now the VPN only while it carries the IPv4 default route in netstat: an unscoped default row, or both 0/1 and 128.0/1 rows on it. A default row scoped to a tunnel (flag I) does not count; on the physical interface it still does, since a VPN holding the default leaves the physical default scoped. Tests feed netstat text in the macOS layout through the parser into Select. Not run on a real Mac. Model: opus-5-5
387 lines
10 KiB
Go
387 lines
10 KiB
Go
// Package netdetect chooses which network interfaces rtnetmon should monitor.
|
|
//
|
|
// The host-specific queries (enumerating interfaces, reading the routing
|
|
// table) live behind small data types so the selection logic and the route
|
|
// parsers are pure functions that can be unit-tested on any OS with fake
|
|
// data. Only the real routing-table query is build-tagged per platform.
|
|
package netdetect
|
|
|
|
import (
|
|
"encoding/hex"
|
|
"errors"
|
|
"fmt"
|
|
"net"
|
|
"sort"
|
|
"strings"
|
|
)
|
|
|
|
// Selection failures. Those needing the offending interface names are
|
|
// wrapped with %w at the call site.
|
|
var (
|
|
errUnsupportedOS = errors.New("unsupported operating system")
|
|
errOneOfPair = errors.New(
|
|
"found only one of the configured interfaces; " +
|
|
"rtnetmon needs both, or neither (default route only)")
|
|
errNoDefaultRoute = errors.New(
|
|
"no default route found; rtnetmon needs one internet interface")
|
|
errManyDefaultRoutes = errors.New(
|
|
"multiple default-route interfaces found; rtnetmon supports only one")
|
|
errNoPhysRoute = errors.New(
|
|
"no physical default-route interface found; " +
|
|
"rtnetmon needs one internet interface")
|
|
errManyPhysRoutes = errors.New(
|
|
"multiple physical default-route interfaces found; " +
|
|
"rtnetmon supports only one")
|
|
)
|
|
|
|
// Interface is a network interface reduced to what detection needs.
|
|
type Interface struct {
|
|
Name string
|
|
Up bool
|
|
IPv4 []string
|
|
}
|
|
|
|
// Route is one routing-table entry reduced to what detection needs. Scoped
|
|
// marks a macOS interface-scoped route (flag I), which only traffic bound to
|
|
// that interface uses.
|
|
type Route struct {
|
|
Iface string
|
|
Gateway string
|
|
Default bool
|
|
Scoped bool
|
|
}
|
|
|
|
// Pane names one interface to display, with its label.
|
|
type Pane struct {
|
|
Name string
|
|
Label string
|
|
}
|
|
|
|
// Flags carries the user's --iface/--label choices and whether each label was
|
|
// set explicitly on the command line.
|
|
type Flags struct {
|
|
IfaceA string
|
|
LabelA string
|
|
IfaceB string
|
|
LabelB string
|
|
LabelASet bool
|
|
LabelBSet bool
|
|
}
|
|
|
|
// Interfaces enumerates the host's interfaces and their IPv4 addresses. This
|
|
// uses the standard library and is the same on every platform.
|
|
func Interfaces() ([]Interface, error) {
|
|
ifs, err := net.Interfaces()
|
|
if err != nil {
|
|
return nil, fmt.Errorf("listing interfaces: %w", err)
|
|
}
|
|
|
|
out := make([]Interface, 0, len(ifs))
|
|
for _, ifi := range ifs {
|
|
var v4 []string
|
|
|
|
addrs, _ := ifi.Addrs()
|
|
for _, a := range addrs {
|
|
if n, ok := a.(*net.IPNet); ok && n.IP.To4() != nil {
|
|
v4 = append(v4, n.IP.String())
|
|
}
|
|
}
|
|
|
|
out = append(out, Interface{
|
|
Name: ifi.Name,
|
|
Up: ifi.Flags&net.FlagUp != 0,
|
|
IPv4: v4,
|
|
})
|
|
}
|
|
|
|
return out, nil
|
|
}
|
|
|
|
// Select decides which one or two interfaces to monitor for the given OS.
|
|
// See the README's supported matrix for the exact rules.
|
|
func Select(goos string, ifaces []Interface, routes []Route, f Flags) ([]Pane, error) {
|
|
switch goos {
|
|
case "linux":
|
|
return selectLinux(ifaces, routes, f)
|
|
case "darwin":
|
|
return selectDarwin(ifaces, routes, f)
|
|
default:
|
|
return nil, fmt.Errorf("%w: %q", errUnsupportedOS, goos)
|
|
}
|
|
}
|
|
|
|
// selectLinux keeps today's behavior: if both configured interfaces exist,
|
|
// monitor them as two panes; if neither exists, monitor the single
|
|
// default-route interface; anything else is an error.
|
|
func selectLinux(ifaces []Interface, routes []Route, f Flags) ([]Pane, error) {
|
|
haveA := hasInterface(ifaces, f.IfaceA)
|
|
haveB := hasInterface(ifaces, f.IfaceB)
|
|
|
|
switch {
|
|
case haveA && haveB:
|
|
return []Pane{
|
|
{Name: f.IfaceA, Label: f.LabelA},
|
|
{Name: f.IfaceB, Label: f.LabelB},
|
|
}, nil
|
|
case !haveA && !haveB:
|
|
name, err := onlyDefaultRoute(routes)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
return []Pane{{Name: name, Label: singleLabel(f)}}, nil
|
|
default:
|
|
return nil, fmt.Errorf("%w (%q, %q)", errOneOfPair, f.IfaceA, f.IfaceB)
|
|
}
|
|
}
|
|
|
|
// selectDarwin monitors the physical default-route interface, plus a VPN
|
|
// tunnel as the primary pane while one is connected.
|
|
func selectDarwin(ifaces []Interface, routes []Route, f Flags) ([]Pane, error) {
|
|
vpn := findVPN(ifaces, routes)
|
|
|
|
phys, err := onlyPhysicalDefaultRoute(routes, vpn)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
if vpn == "" {
|
|
return []Pane{{Name: phys, Label: singleLabel(f)}}, nil
|
|
}
|
|
|
|
return []Pane{
|
|
{Name: vpn, Label: labelOr(f.LabelA, f.LabelASet, "VPN")},
|
|
{Name: phys, Label: labelOr(f.LabelB, f.LabelBSet, "default route")},
|
|
}, nil
|
|
}
|
|
|
|
// findVPN returns the name of the connected VPN tunnel, or "" if there is
|
|
// none. A tunnel is the VPN only while it carries the default route; one that
|
|
// is merely up, even with a routable address (Tailscale without an exit node,
|
|
// or a tunnel a disconnected client left behind), is not. A default route
|
|
// scoped to the tunnel does not count: only traffic bound there uses it.
|
|
func findVPN(ifaces []Interface, routes []Route) string {
|
|
routeIfaces := map[string]bool{}
|
|
|
|
for _, r := range routes {
|
|
if r.Default && !r.Scoped {
|
|
routeIfaces[r.Iface] = true
|
|
}
|
|
}
|
|
|
|
sorted := append([]Interface(nil), ifaces...)
|
|
sort.Slice(sorted, func(i, j int) bool { return sorted[i].Name < sorted[j].Name })
|
|
|
|
for _, ifi := range sorted {
|
|
if !isTunnel(ifi.Name) {
|
|
continue
|
|
}
|
|
|
|
if routeIfaces[ifi.Name] {
|
|
return ifi.Name
|
|
}
|
|
}
|
|
|
|
return ""
|
|
}
|
|
|
|
// onlyDefaultRoute returns the single default-route interface, or an error if
|
|
// there is not exactly one.
|
|
func onlyDefaultRoute(routes []Route) (string, error) {
|
|
names := defaultRouteIfaces(routes, "")
|
|
|
|
switch len(names) {
|
|
case 1:
|
|
return names[0], nil
|
|
case 0:
|
|
return "", errNoDefaultRoute
|
|
default:
|
|
return "", fmt.Errorf("%w (%s)",
|
|
errManyDefaultRoutes, strings.Join(names, ", "))
|
|
}
|
|
}
|
|
|
|
// onlyPhysicalDefaultRoute returns the single non-tunnel default-route
|
|
// interface (ignoring the VPN), or an error if there is not exactly one.
|
|
func onlyPhysicalDefaultRoute(routes []Route, vpn string) (string, error) {
|
|
names := defaultRouteIfaces(routes, vpn)
|
|
|
|
switch len(names) {
|
|
case 1:
|
|
return names[0], nil
|
|
case 0:
|
|
return "", errNoPhysRoute
|
|
default:
|
|
return "", fmt.Errorf("%w (%s)",
|
|
errManyPhysRoutes, strings.Join(names, ", "))
|
|
}
|
|
}
|
|
|
|
// defaultRouteIfaces returns the sorted, unique interface names that carry a
|
|
// default route, excluding the named VPN interface and any other tunnel.
|
|
// Scoped routes count: while a VPN holds the default route, the physical
|
|
// interface keeps only a default route scoped to itself.
|
|
func defaultRouteIfaces(routes []Route, vpn string) []string {
|
|
seen := map[string]bool{}
|
|
|
|
var names []string
|
|
|
|
for _, r := range routes {
|
|
if !r.Default || r.Iface == vpn || isTunnel(r.Iface) || seen[r.Iface] {
|
|
continue
|
|
}
|
|
|
|
seen[r.Iface] = true
|
|
names = append(names, r.Iface)
|
|
}
|
|
|
|
sort.Strings(names)
|
|
|
|
return names
|
|
}
|
|
|
|
// hasInterface reports whether an interface with the given name exists.
|
|
func hasInterface(ifaces []Interface, name string) bool {
|
|
for _, ifi := range ifaces {
|
|
if ifi.Name == name {
|
|
return true
|
|
}
|
|
}
|
|
|
|
return false
|
|
}
|
|
|
|
// isTunnel reports whether the interface name is a macOS userspace tunnel
|
|
// (utunN), which is what Mullvad and other WireGuard/OpenVPN clients use.
|
|
func isTunnel(name string) bool {
|
|
return strings.HasPrefix(name, "utun")
|
|
}
|
|
|
|
// singleLabel is the label for a lone pane: the explicit --labelA if given,
|
|
// otherwise a plain description.
|
|
func singleLabel(f Flags) string {
|
|
return labelOr(f.LabelA, f.LabelASet, "default route")
|
|
}
|
|
|
|
// labelOr returns value when it was set explicitly, otherwise fallback.
|
|
func labelOr(value string, set bool, fallback string) string {
|
|
if set {
|
|
return value
|
|
}
|
|
|
|
return fallback
|
|
}
|
|
|
|
// parseIPRoute reads `ip -4 route show default` output. Every printed line is
|
|
// a default route.
|
|
func parseIPRoute(out string) []Route {
|
|
var routes []Route
|
|
|
|
for _, line := range strings.Split(out, "\n") {
|
|
fields := strings.Fields(line)
|
|
if len(fields) == 0 || fields[0] != "default" {
|
|
continue
|
|
}
|
|
|
|
r := Route{Default: true}
|
|
|
|
for i := range len(fields) - 1 {
|
|
switch fields[i] {
|
|
case "dev":
|
|
r.Iface = fields[i+1]
|
|
case "via":
|
|
r.Gateway = fields[i+1]
|
|
}
|
|
}
|
|
|
|
if r.Iface != "" {
|
|
routes = append(routes, r)
|
|
}
|
|
}
|
|
|
|
return routes
|
|
}
|
|
|
|
// parseProcNetRoute reads /proc/net/route. A default route has destination
|
|
// 00000000; the gateway is a little-endian hex IPv4 address.
|
|
func parseProcNetRoute(out string) []Route {
|
|
var routes []Route
|
|
|
|
for i, line := range strings.Split(out, "\n") {
|
|
if i == 0 { // column header
|
|
continue
|
|
}
|
|
|
|
fields := strings.Fields(line)
|
|
if len(fields) < 3 || fields[1] != "00000000" {
|
|
continue
|
|
}
|
|
|
|
routes = append(routes, Route{
|
|
Iface: fields[0],
|
|
Gateway: hexToIP(fields[2]),
|
|
Default: true,
|
|
})
|
|
}
|
|
|
|
return routes
|
|
}
|
|
|
|
// parseNetstat reads `netstat -rn -f inet` output (macOS); the Netif column
|
|
// (field 4) names the interface. A row whose destination is "default" is a
|
|
// default route, scoped when its flags include I. A "0/1" row and a "128.0/1"
|
|
// row on one interface together also make a default route there: VPN clients
|
|
// that leave the physical default in place send all traffic through them.
|
|
func parseNetstat(out string) []Route {
|
|
const columns = 4 // Destination, Gateway, Flags, Netif; Expire is optional
|
|
|
|
var routes []Route
|
|
|
|
var lowHalf []string // interfaces with a 0/1 row
|
|
|
|
highHalf := map[string]bool{} // interfaces with a 128.0/1 row
|
|
|
|
for _, line := range strings.Split(out, "\n") {
|
|
fields := strings.Fields(line)
|
|
if len(fields) < columns {
|
|
continue
|
|
}
|
|
|
|
dest, gateway, flags, iface := fields[0], fields[1], fields[2], fields[3]
|
|
|
|
switch dest {
|
|
case "default":
|
|
routes = append(routes, Route{
|
|
Iface: iface,
|
|
Gateway: gateway,
|
|
Default: true,
|
|
Scoped: strings.Contains(flags, "I"),
|
|
})
|
|
case "0/1":
|
|
lowHalf = append(lowHalf, iface)
|
|
case "128.0/1":
|
|
highHalf[iface] = true
|
|
}
|
|
}
|
|
|
|
for _, iface := range lowHalf {
|
|
if highHalf[iface] {
|
|
routes = append(routes, Route{Iface: iface, Default: true})
|
|
}
|
|
}
|
|
|
|
return routes
|
|
}
|
|
|
|
// hexToIP converts a little-endian hex IPv4 address (as found in
|
|
// /proc/net/route) to dotted-quad form.
|
|
func hexToIP(h string) string {
|
|
b, err := hex.DecodeString(h)
|
|
if err != nil || len(b) != net.IPv4len {
|
|
return ""
|
|
}
|
|
|
|
// /proc/net/route stores the address little-endian.
|
|
return net.IPv4(b[3], b[2], b[1], b[0]).String()
|
|
}
|